πΊπΈ
TPI-Abuse
2026-09-29 07:14:57
(5 minutes ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 03:14:52.716342 2026] [security2:error] [pid 31112:tid 31130] [client 162.158.154.71:12081] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thecraftsycat.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thecraftsycat.com"] [uri "/index.php.bak"] [unique_id "artlbKFcke_Mfh9v0aYqOwAAAI4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 21:27:52
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 17:27:44.535540 2026] [security2:error] [pid 4364:tid 4364] [client 162.158.154.71:12616] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kathyquan.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kathyquan.com"] [uri "/index.php.bak"] [unique_id "arrb0EqqCklcweCY7TUkIwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 18:39:53
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 162.158.154.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.154.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 14:39:47.982338 2026] [security2:error] [pid 1230:tid 1230] [client 162.158.154.71:10753] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||paintscapeabroad.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "paintscapeabroad.com"] [uri "/index.php.bak"] [unique_id "arq0cyPzJ_pwkfwEfASgogAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-09-22 03:27:34
(1 week ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 15:33:31
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 11:33:26.863389 2026] [security2:error] [pid 2118511:tid 2118562] [client 162.158.154.71:11844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.vivierae.com"] [uri "/.git/config"] [unique_id "ao21xg3boPt_upTV_JjVSQAAAUM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
abdubhai
2026-08-19 13:01:25
(1 month ago)
162.158.154.71 - - [19/Aug/2026:
...
Brute-Force
πΊπΈ
octageeks.com
2026-04-10 04:09:06
(5 months ago)
Wordpress malicious attack:[octawp]
Web App Attack
πΊπΈ
mnsf
2026-04-04 01:06:12
(5 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
πΊπΈ
mawan
2026-03-23 15:42:05
(6 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-21 04:02:48
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 00:02:43.335468 2026] [security2:error] [pid 12289:tid 12289] [client 162.158.154.71:9996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.i-med.com"] [uri "/public/.env"] [unique_id "ab4YY_5leHbp3WO3B6fXagAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-21 00:52:15
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 20:52:12.327371 2026] [security2:error] [pid 7700:tid 7700] [client 162.158.154.71:12154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.globalpackets.net"] [uri "/.env_settings"] [unique_id "ab3rvBDV6x9RHevsX88nGgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 08:07:17
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:07:12.631984 2026] [security2:error] [pid 10381:tid 10381] [client 162.158.154.71:12561] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.darkestdaysclan.com"] [uri "/.env.save"] [unique_id "ab0AMNWu6KsxXNXLeduNoAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 07:20:48
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:20:38.496214 2026] [security2:error] [pid 11826:tid 11826] [client 162.158.154.71:12093] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.littlebiglebanon.com"] [uri "/.env.development"] [unique_id "abz1RnAAL567-TVsW9NvKAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 05:57:36
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:57:31.271307 2026] [security2:error] [pid 20610:tid 20610] [client 162.158.154.71:14255] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.sekizinci.com"] [uri "/.env.bak"] [unique_id "abzhyxMQmz2wMI1F--FOpwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
octageeks.com
2026-03-20 04:11:46
(6 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack